OceanAltOceanAlt

KYA (Know Your Agent)

KYA(Know Your Agent)

Attributing identity to an AI agent that initiates payments: who it is, which legal entity stands behind it, what it is authorized to do, and whether that authorization can be revoked. The difference from KYC is the subject — KYC identifies a person, KYA identifies the program spending on that person's behalf. Worth stressing: KYA only answers who is behind it. That is not payment security in itself; the real protection is enforcement before the money leaves.

In plainer words

We know KYC (Know Your Customer): opening a bank account requires proving "you are you." KYA applies the same idea to AI agents — Know Your Agent, giving a spending agent an "ID card." It answers four questions: who is this agent? Which accountable entity (company, person) stands behind it? What is it authorized to do? And can it be revoked in one click if something goes wrong? KYC identifies a person; KYA identifies the program spending on that person's behalf. Why is it needed? An agent's ID isn't secret, and an ID alone can't prove "you are that agent" — like knowing a name isn't being the person. If a system checks the ID but not a credential, anyone with your agent's ID could spend against your budget (a hole we actually broke on our own gateway once, now fixed). One emphasis: KYA only answers who's behind it — it isn't payment security by itself. The real protection is the sequence of enforced gates before the money leaves. KYA is the first, not the whole.

RELATED TERMS

  • MandateThe boundary within which an agent may spend — typically a p
  • x402A machine-payment interaction built on the HTTP 402 status c

This definition is citable at a stable URL: https://oceanalt.com/en/glossary/kya

← Back to the glossary